Security & Privacy

Clinical tools.Clear data boundaries.

Write progress notes, worksheets and session prep without Reframe storing your session text on its servers. Progress notes, worksheets, session prep and Thinking Partner run on Amazon Web Services under Amazon's Business Associate Agreement with Reframe. Sharing is paused for now.

How it works: Your browser sends your session summary to Reframe's clinical application on Amazon Web Services, which requests the draft from Amazon Bedrock. The draft returns to your browser for review, copying, local saving or export. Reframe keeps usage counts and, for progress notes, audit records, not your session text.

Reframe Practice is a tool for licensed therapists, not a therapy clinic or counseling service.

Data Flow

From your browser and back

  1. 01

    Your browser

    You enter clinical context and request a note or worksheet.

  2. 02

    Reframe on AWS

    Reframe's clinical application on Amazon Web Services receives the request and sends the prompt to Amazon Bedrock.

  3. 03

    Amazon Bedrock

    Anthropic's Claude Haiku 4.5 model, run by AWS, drafts the note, worksheet or session guide and returns it through Reframe.

  4. 04

    Your browser

    Review the draft, then save or export it. Anything you save to your library stays in your browser.

How It Works

What does zero retention mean here?

Reframe does not store the session text you submit or the draft it returns on the server. Other data paths have different storage rules.

Generation, saving and sharing are separate choices. A worksheet saved in your browser is local to that browser profile. Sharing is paused for now; a share link stored an encrypted copy in Reframe's share store. Account details, usage counts and requested practice-service work are stored separately.

Reframe's AWS account sets Amazon Bedrock's data retention mode to none and does not turn on model invocation logging. A browser test cannot confirm provider settings. Review the Amazon Bedrock data retention documentation and our Privacy Policy for more detail.

Keeping clinical text out of the main database reduces retained content. It does not eliminate every security or legal risk.

Your Saving and Sharing Choices

Generate a draft. Save it on your device. Share an encrypted copy only when you choose.

Account records and usage counts remain separate from the clinical text.

Browser Inspection

See what your browser sends.

Use invented sample text to inspect a generation request. This shows browser behavior; it is not an audit of backend retention.

1

Open your browser Developer Tools

Right-click anywhere on the page, select "Inspect", then click the "Network" tab to view requests made while it is recording.

2

Generate a note or worksheet

Use invented sample text, select a format, and generate. Keep real client information out of demonstration captures.

3

Watch the Network tab

Inspect the generation request and response. You may also see account or usage requests. The Network tab does not show what happens inside Reframe or AWS after a request arrives.

4

Check local saving separately

Saved browser content can remain until you remove it or clear browser data. A draft disappearing after refresh does not prove that a server deleted anything.

Browser inspection has limits.

It cannot verify server logs, provider retention settings or legal compliance. Review the documented processing and storage boundaries too.

What This Means

What this means for you

No clinical archive

The clinical generation flow does not create a plain-text archive of notes or worksheets in Reframe's main database. Account and usage records still exist.

Local saving

Your browser library and exported files are your copies. Protect that device and retain the records you need; Reframe cannot restore a cleared browser library.

Named processors

Progress notes, worksheets, session prep and Thinking Partner pass through Reframe's application on Amazon Web Services and Amazon Bedrock. Account, billing and service information goes to the providers described in our Privacy Policy.

Optional sharing

Sharing is paused for now. A share link stores an encrypted worksheet copy and metadata. Anyone with the complete link, including its decryption key, can view the worksheet while the link is valid.

Data Handling

What goes where

Data
Handling
Progress notes, worksheets, session prep and Thinking Partner
Processed by Reframe's application on Amazon Web Services and Amazon Bedrock, under Amazon's Business Associate Agreement with Reframe. Reframe does not store the session text on the server. Progress notes are copied out, not saved in the app.
Saved worksheets and session guides
Kept in your browser library or in files you export.
Optional worksheet shares
Encrypted content and link metadata are stored on the server. The complete share link includes the decryption key.
Account and billing
Account and subscription records are stored in Supabase. Payments are processed by Stripe.
Usage and operations
Usage counts, audit records, limited product events and hosting logs are kept without session text.
Practice services
Submitted professional practice details and assessment results are retained to provide the requested service.

Review the full account, provider and service data details.

Read our Privacy Policy →
Transparency

What we do collect

To be completely transparent, here's what we do store:

  • Your email address (for account access)
  • Your therapist profile (name, credentials, practice info)
  • Subscription status and usage counts
  • Limited first-party product events, public-page analytics and operational request logs
  • Practice details, assessment results and service requests you submit
  • Feedback you explicitly choose to submit
  • Encrypted share-link data only if you choose to create a secure share link

Encrypted worksheet sharing is an exception to local-only output storage. A share link includes a decryption key and expires after the selected period. Expiration prevents further access through the link; it is not a promise of immediate deletion from every storage layer.

Technical Details

For those who want the details

Encryption

HTTPS encrypts data in transit. Optional worksheet shares use encryption in the browser before upload.

Processing

Progress note, worksheet, session prep and Thinking Partner requests go to Reframe's application on Amazon Web Services and Amazon Bedrock in US AWS Regions. Bedrock data retention is set to none and model invocation logging is off.

Rendering

Generated clinical text returns to your browser for review.

PDF Export

Clinical worksheet PDFs are generated in your browser.

Local Storage

The clinical library belongs to that browser profile. Reframe does not provide a server backup of that library.

Share Links

The share store receives encrypted worksheet content and metadata. The key is kept in the URL fragment and is not included in the share API request.

Analytics

Public-page analytics are separate from bounded first-party tool events. Clinical text must not be included in either.

Questions

Security FAQ

How does Reframe support HIPAA-related requirements?

Progress notes, worksheets, session prep and Thinking Partner run on Amazon Web Services under Amazon's Business Associate Agreement with Reframe. That agreement does not by itself make any particular use HIPAA compliant; your practice's own safeguards matter too. If your practice needs its own BAA with Reframe, contact us and we will talk it through.

What if I need to recover a note or worksheet?

Saved worksheets and session guides live in that browser profile or in files you export. Reframe cannot restore a cleared browser library. An optional share link provides access to the shared worksheet while valid; it is not an account backup.

Do you train AI on my clinical content?

Reframe does not use your clinical text to train models. Progress notes, worksheets, session guides and Thinking Partner responses are drafted by Anthropic's Claude Haiku 4.5 model through Amazon Bedrock, and AWS states that model providers such as Anthropic do not have access to Bedrock prompts and completions.

What can I verify in my browser?

Developer Tools can show requests between your browser and Reframe. They cannot prove what backend services store, what server logs contain or how AWS handles retention. Refreshing a page is not evidence of server-side deletion.

What should I check before entering client PHI?

Use the minimum clinical detail needed and avoid names and other identifiers where possible. Before entering protected health information, confirm your practice's approved workflow and applicable agreements. Technical features alone do not establish compliance for every use.

For the responsibilities that accompany cloud processing, see HHS guidance on HIPAA and cloud computing. For a BAA or a question about your workflow, contact Reframe.

Privacy First

See the architecture in action.

Start with 20 free notes every 30 days with a free account. Pro removes the note cap for USD 29/month.View Free and Pro pricing

Clinical Generation * Browser-Based Saving * Built by a Therapist